Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1061 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Command and Control
Analytics BIOC Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection, Reconnaissance
Analytics BIOC Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Collection
Analytics BIOC Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Unusual process accessed web browser cookies An unusual process has accessed a web browser's session cookie store. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. Medium Cortex Cloud XDR Agent Execution
Analytics BIOC Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Unusual resource access by Azure application An Azure application had interacted with an unusual resource using the Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual secret management activity A cloud Identity performed a secret management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access
Analytics BIOC Unusual sender IP subnet This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Unusual SSH activity that resembles SSH proxy A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control
Analytics BIOC Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unusual weak authentication by user A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC Unverified domain added to Azure AD A new unverified domain was added to Azure AD. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Usage of homograph characters detected in an email Detected characters resembling Latin letters within an email's subject and/or body. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Usage of homograph characters detected in an email's from header Detected characters resembling Latin letters within an email's From header. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Collection
Analytics BIOC User account delegation change A user account was modified with delegation to a service. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC User added a new device to Okta Verify instance The user has successfully registered a new device with the Okta Verify application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Persistence
Analytics BIOC User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Defense Evasion
Analytics BIOC User attempted to connect from a suspicious country A user connected from an unusual country. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
Analytics BIOC User installed an application in Microsoft Teams via Graph API A user who rarely uses the Graph API to install Microsoft Teams applications has installed one using it. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Microsoft Graph Logs Persistence
Analytics BIOC User set insecure CA registry setting for global SANs A user enabled the EDITF_ATTRIBUTESUBJECTALTNAME2 registry flag, allowing custom Subject Alternative Names (SANs) to be specified on all certificate templates. This could enable attackers to bypass security controls by requesting certificates with user-defined SANs. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC User signed in to an application via Power Automate for the first time A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Exfiltration
Analytics BIOC VM Detection attempt A script has executed commands that can be used to detect VM environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. Informational Platform Analytics XDR Agent Defense Evasion, Discovery
Analytics BIOC VPN access with an abnormal operating system A user accessed a VPN with an abnormal operating system. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC VPN login attempt by a honey user A VPN login attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion
Analytics BIOC VPN login by a service account A service account attempted to log in to a VPN service. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC VPN login with a machine account A machine account successfully logged in to a VPN service. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. High Platform Analytics XDR Agent Impact
Analytics BIOC Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Defense Evasion, Persistence
Analytics BIOC Weakly-Encrypted Kerberos Ticket Requested A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes and is typically a sign of a Kerberoasting attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. Informational Platform Analytics XDR Agent Initial Access, Persistence
Analytics BIOC WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Well-known brand in sender headers with header inconsistencies Sender headers include a well-known brand with header inconsistencies indicating possible impersonation. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows Event Log was cleared using wevtutil.exe A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. Low Platform Analytics XDR Agent Impact
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Windows Installer exploitation for local privilege escalation The Windows installer (msiexec.exe) was likely exploited to run a malicious rollback script (.rbs file) instead of the original. Users should not be able to modify config.msi during the installation process, only SYSTEM should have access to it. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Windows LOLBIN executable connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Medium Platform Analytics XDR Agent Command and Control
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). Informational Email Security Microsoft 365 Emails Initial Access, Defense Evasion, Execution